CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (22 December 2025)

Published: Loading…

At a Glance

  • A malicious npm package posing as a WhatsApp Web API library exceeded 56,000 downloads before being exposed stealing messages and authentication tokens.
  • Iranian-linked Infy, also known as Prince of Persia, resurfaced with updated Foudre and Tonnerre malware after nearly five years of inactivity.
  • Docker open sourced more than 1,000 Docker Hardened Images under Apache 2.0 to reduce container attack surfaces.
  • Google announced the retirement of its Dark Web Report service as part of a broader shutdown of legacy security features.
  • Researchers observed rapid growth in AI-generated phishing websites built with automated site creation tools.

Summary

Software supply-chain abuse remained prominent as a malicious npm package impersonating a WhatsApp Web API library surpassed 56,000 downloads. The package intercepted messages, contacts, media, and authentication tokens while covertly linking attacker-controlled devices to victims’ WhatsApp accounts.

Nation-state espionage activity resurfaced with the return of Infy (Prince of Persia), an Iranian-linked threat actor dormant for several years. Researchers identified new Foudre and Tonnerre malware variants, expanded command-and-control infrastructure, and continued targeting across Europe and the Middle East.

Phishing operations increasingly relied on automation, with AI-powered website builders enabling large volumes of realistic scam sites. Researchers observed hundreds of newly generated phishing pages daily, cloning financial, cryptocurrency, and e-commerce brands with minimal technical effort.

On the defensive side, Docker released more than 1,000 Docker Hardened Images as free and open source, providing minimal base images, verifiable provenance, and reduced attack surface for containerised applications.

Service reliability and legacy tooling also drew attention after Google confirmed the shutdown of its Dark Web Report alert service. Separately, a NIST attempt to disable Network Time Protocol infrastructure following an atomic clock drift incident highlighted operational sensitivity in time synchronisation systems.

Today’s selected highlights expand on the malicious npm WhatsApp spyware, the resurgence of the Iranian Infy APT, Docker’s hardened container images, and the rise of AI-generated phishing websites.

Highlights of the Day

Malicious npm Package Spied on WhatsApp Accounts

A malicious npm package disguised as a WhatsApp Web API library accumulated more than 56,000 downloads before being identified as spyware. The package secretly intercepted messages, contacts, media, and authentication tokens, while also linking attackers’ devices to victims’ WhatsApp accounts through a hidden backdoor. Its functional code, heavy obfuscation, and persistence mechanisms allowed it to evade detection for months.

Iranian APT Resurfaces With Expanded Malware Infrastructure

Researchers have identified renewed and expanded activity from the Iranian-linked “Prince of Persia” threat group after several years of apparent inactivity. The campaign uses updated Foudre and Tonnerre malware variants, multiple command-and-control servers, and Telegram-based infrastructure to manage victims and exfiltrate data across Iran, Europe, and beyond. Analysis shows increased operational scale, more complex domain generation techniques, and continued targeting aligned with long-running state-sponsored espionage objectives.

Source: SafeBreach

Docker Opens Hardened Container Images to All Developers

Docker has made its hardened container images freely available and open source, expanding access to security-focused base images across the container ecosystem. The images are designed to reduce attack surface, provide transparent vulnerability data, and include verifiable build provenance, while remaining compatible with common Linux distributions. The move reflects Docker’s broader effort to strengthen software supply chain security amid growing container adoption.

Source: Docker

AI Web Builders Fuel Surge in Phishing Websites

Researchers report a sharp rise in phishing and scam sites created using AI-powered website builders that can clone trusted brands with minimal effort. These tools enable realistic, localised replicas of banking, cryptocurrency, and e-commerce sites, significantly lowering technical barriers for fraud operations. Analysis indicates hundreds of new AI-generated malicious websites appearing daily across multiple regions.

Daily Coverage

Developments
Malicious Npm SpywareInfy Apt ResurgenceDocker Hardened ImagesAi Phishing Sites
Vulnerabilities
CVE-2025-59374"Unsupported When Assigned" Certain Versions Of The Asus Live Update Client Were Distributed With Unauthorized Modifications Introduced Through A Supply Chain Compromise. The Modified Builds Could Cause Devices Meeting Specific Targeting Conditions To Perform Unintended Actions. Only Devices That Met These Conditions And Installed The Compromised Versions Were Affected. The Live Update Client Has Already Reached End-Of-Support (Eos) In October 2021, And No Currently Supported Devices Or Products…CVE-2025-14733Fireware Os 11.10.2 (Critical)